<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Cisco IOS Order of Operation &#8211; Updated, Again</title>
	<atom:link href="http://etherealmind.com/cisco-ios-order-of-operation/feed/" rel="self" type="application/rss+xml" />
	<link>http://etherealmind.com/cisco-ios-order-of-operation/</link>
	<description>Network design, architecture, thinking, working. Tech.</description>
	<lastBuildDate>Fri, 10 Feb 2012 18:43:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: pugalendi dhanapal</title>
		<link>http://etherealmind.com/cisco-ios-order-of-operation/#comment-1226</link>
		<dc:creator>pugalendi dhanapal</dc:creator>
		<pubDate>Wed, 14 Sep 2011 05:39:00 +0000</pubDate>
		<guid isPermaLink="false">http://etherealmind.com/?p=1697#comment-1226</guid>
		<description>Good Info , Great </description>
		<content:encoded><![CDATA[<p>Good Info , Great</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pugalendi dhanapal</title>
		<link>http://etherealmind.com/cisco-ios-order-of-operation/#comment-1227</link>
		<dc:creator>pugalendi dhanapal</dc:creator>
		<pubDate>Wed, 14 Sep 2011 05:39:00 +0000</pubDate>
		<guid isPermaLink="false">http://etherealmind.com/?p=1697#comment-1227</guid>
		<description>Good , great info</description>
		<content:encoded><![CDATA[<p>Good , great info</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: roberto taccon</title>
		<link>http://etherealmind.com/cisco-ios-order-of-operation/#comment-1225</link>
		<dc:creator>roberto taccon</dc:creator>
		<pubDate>Fri, 16 Apr 2010 10:30:54 +0000</pubDate>
		<guid isPermaLink="false">http://etherealmind.com/?p=1697#comment-1225</guid>
		<description>http://www.google.com/profiles/roberto.taccon#buzz

CISCO IOS OOO (Order Of Operation) 

attached an updated diagram by Gregg Schudel 

the original diagram @ pag.120 Chapter 3: IP Network Traffic Plane Security Concepts on 
Router Security Strategies: Securing IP Network Traffic Planes 
http://www.ciscopress.com/bookstore/product.asp?isbn=1587053365

http://lh3.googleusercontent.com/_pYguWUnPyho/S8g3bZWvDCI/AAAAAAAAADo/zTqaSSgb1ZA/IOS-OOO.PNG</description>
		<content:encoded><![CDATA[<p><a href="http://www.google.com/profiles/roberto.taccon#buzz" rel="nofollow">http://www.google.com/profiles/roberto.taccon#buzz</a></p>
<p>CISCO IOS OOO (Order Of Operation) </p>
<p>attached an updated diagram by Gregg Schudel </p>
<p>the original diagram @ pag.120 Chapter 3: IP Network Traffic Plane Security Concepts on<br />
Router Security Strategies: Securing IP Network Traffic Planes<br />
<a href="http://www.ciscopress.com/bookstore/product.asp?isbn=1587053365" rel="nofollow">http://www.ciscopress.com/bookstore/product.asp?isbn=1587053365</a></p>
<p><a href="http://lh3.googleusercontent.com/_pYguWUnPyho/S8g3bZWvDCI/AAAAAAAAADo/zTqaSSgb1ZA/IOS-OOO.PNG" rel="nofollow">http://lh3.googleusercontent.com/_pYguWUnPyho/S8g3bZWvDCI/AAAAAAAAADo/zTqaSSgb1ZA/IOS-OOO.PNG</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CraigW</title>
		<link>http://etherealmind.com/cisco-ios-order-of-operation/#comment-1224</link>
		<dc:creator>CraigW</dc:creator>
		<pubDate>Wed, 09 Sep 2009 14:57:31 +0000</pubDate>
		<guid isPermaLink="false">http://etherealmind.com/?p=1697#comment-1224</guid>
		<description>ZBF is tricky and I don&#039;t know the answer. As you say, zone pairs are determined after PBR/routing. It would seem that ZBF ingress/egress policies are probably only applied at egress (or egress to &quot;self&quot;), using a cached copy of the original pre-NAT packet. But that&#039;s just a guess. If you have  the time and patience to go through a battery of tests, correlate ZBF behavior with NAT translations, ACL counters, and Netflow records, and you should get a good view of how it fits (please let me know).

For &quot;nat enable&quot; (NVI), my OOO shows it taking place along with NAT inside-to-outside. I.e., WCCP should occur before &quot;nat enable&quot;</description>
		<content:encoded><![CDATA[<p>ZBF is tricky and I don&#8217;t know the answer. As you say, zone pairs are determined after PBR/routing. It would seem that ZBF ingress/egress policies are probably only applied at egress (or egress to &#8220;self&#8221;), using a cached copy of the original pre-NAT packet. But that&#8217;s just a guess. If you have  the time and patience to go through a battery of tests, correlate ZBF behavior with NAT translations, ACL counters, and Netflow records, and you should get a good view of how it fits (please let me know).</p>
<p>For &#8220;nat enable&#8221; (NVI), my OOO shows it taking place along with NAT inside-to-outside. I.e., WCCP should occur before &#8220;nat enable&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Greg Ferro</title>
		<link>http://etherealmind.com/cisco-ios-order-of-operation/#comment-1223</link>
		<dc:creator>Greg Ferro</dc:creator>
		<pubDate>Wed, 09 Sep 2009 10:05:04 +0000</pubDate>
		<guid isPermaLink="false">http://etherealmind.com/?p=1697#comment-1223</guid>
		<description>I suspect that this is why Cisco doesn&#039;t publish an absolute reference because the ACTUAL order varies from platform to platform, possibly different in code releases. 

Still, the above is a good guide until proven otherwise.</description>
		<content:encoded><![CDATA[<p>I suspect that this is why Cisco doesn&#8217;t publish an absolute reference because the ACTUAL order varies from platform to platform, possibly different in code releases. </p>
<p>Still, the above is a good guide until proven otherwise.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Greg Ferro</title>
		<link>http://etherealmind.com/cisco-ios-order-of-operation/#comment-1222</link>
		<dc:creator>Greg Ferro</dc:creator>
		<pubDate>Wed, 09 Sep 2009 10:03:55 +0000</pubDate>
		<guid isPermaLink="false">http://etherealmind.com/?p=1697#comment-1222</guid>
		<description>I don&#039;t have any answers to your questions at the moment. While we could wish for Cisco to publish something definitive, this is probably as good as it gets for now.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t have any answers to your questions at the moment. While we could wish for Cisco to publish something definitive, this is probably as good as it gets for now.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Greg Ferro</title>
		<link>http://etherealmind.com/cisco-ios-order-of-operation/#comment-1221</link>
		<dc:creator>Greg Ferro</dc:creator>
		<pubDate>Wed, 09 Sep 2009 10:02:28 +0000</pubDate>
		<guid isPermaLink="false">http://etherealmind.com/?p=1697#comment-1221</guid>
		<description>Peirky

Thanks for your info, I have updated the post to show the new information and made a copy of 6200networks information. While I like this list, it isn&#039;t &#039;official&#039; so I tend to go with the Networkers version unless proven or needed. I could wish that Cisco would publish a recognised version other than the Nat Order of operations. Something definitive would be good.</description>
		<content:encoded><![CDATA[<p>Peirky</p>
<p>Thanks for your info, I have updated the post to show the new information and made a copy of 6200networks information. While I like this list, it isn&#8217;t &#8216;official&#8217; so I tend to go with the Networkers version unless proven or needed. I could wish that Cisco would publish a recognised version other than the Nat Order of operations. Something definitive would be good.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ivan Pepelnjak</title>
		<link>http://etherealmind.com/cisco-ios-order-of-operation/#comment-1220</link>
		<dc:creator>Ivan Pepelnjak</dc:creator>
		<pubDate>Tue, 08 Sep 2009 18:25:46 +0000</pubDate>
		<guid isPermaLink="false">http://etherealmind.com/?p=1697#comment-1220</guid>
		<description>Well, as I&#039;ve already (probably) commented to Joe&#039;s post, the outside-to-inside NAT is sometimes before the input ACL. See this post in my wiki:

http://wiki.nil.com/NAT_caveats_in_IOS_release_12.4T#Packets_rejected_by_inbound_ACL_generate_NAT_translations</description>
		<content:encoded><![CDATA[<p>Well, as I&#8217;ve already (probably) commented to Joe&#8217;s post, the outside-to-inside NAT is sometimes before the input ACL. See this post in my wiki:</p>
<p><a href="http://wiki.nil.com/NAT_caveats_in_IOS_release_12.4T#Packets_rejected_by_inbound_ACL_generate_NAT_translations" rel="nofollow">http://wiki.nil.com/NAT_caveats_in_IOS_release_12.4T#Packets_rejected_by_inbound_ACL_generate_NAT_translations</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: snetherland</title>
		<link>http://etherealmind.com/cisco-ios-order-of-operation/#comment-1219</link>
		<dc:creator>snetherland</dc:creator>
		<pubDate>Tue, 08 Sep 2009 17:00:18 +0000</pubDate>
		<guid isPermaLink="false">http://etherealmind.com/?p=1697#comment-1219</guid>
		<description>Greg,
Thanks so much for this. I can&#039;t tell you how often during the design and configure stage of a build I&#039;ve had to scour the internet for an order of operations list. I am curious though where zone-based firewall and nat virutal-interfaces fit into this list. For instance, this specifically references when domain-based nat will be performed, but symmetric natting will first send a packet to the NVI and then route it again to the egress interface. Would this mean the nat decision would occur before the outbound WCCP redirect decision? And then with ZBFW your policies are not implemented until a packet crosses between zones. This, as best I can tell, would have to be after the routing decision unless you are using PBR. Would this mean, excluding packets destined to the Self zone, that the only time stateful packet inspection would occur is on the 9th order of the egress operation?

Thanks again for this helpful reference.</description>
		<content:encoded><![CDATA[<p>Greg,<br />
Thanks so much for this. I can&#8217;t tell you how often during the design and configure stage of a build I&#8217;ve had to scour the internet for an order of operations list. I am curious though where zone-based firewall and nat virutal-interfaces fit into this list. For instance, this specifically references when domain-based nat will be performed, but symmetric natting will first send a packet to the NVI and then route it again to the egress interface. Would this mean the nat decision would occur before the outbound WCCP redirect decision? And then with ZBFW your policies are not implemented until a packet crosses between zones. This, as best I can tell, would have to be after the routing decision unless you are using PBR. Would this mean, excluding packets destined to the Self zone, that the only time stateful packet inspection would occur is on the 9th order of the egress operation?</p>
<p>Thanks again for this helpful reference.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pierky</title>
		<link>http://etherealmind.com/cisco-ios-order-of-operation/#comment-1218</link>
		<dc:creator>Pierky</dc:creator>
		<pubDate>Tue, 08 Sep 2009 16:53:09 +0000</pubDate>
		<guid isPermaLink="false">http://etherealmind.com/?p=1697#comment-1218</guid>
		<description>Hi Greg, this is my first comment on your blog, so I would like to thank you for your good work! :)

The table you posted from Cisco is at this URL: http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080133ddd.shtml

At the end of the page we can find &quot;Updated: Sep 30, 2008&quot;.

There is another table too, on 6200networks.com by Joe Harris: http://6200networks.com/2008/09/30/ios-order-of-operation/

This list has more entries than your Net≠work≠ers table, for example it covers reverse crypto maps.
This post also is dated September 30th, 2008!

Who bids more? :)</description>
		<content:encoded><![CDATA[<p>Hi Greg, this is my first comment on your blog, so I would like to thank you for your good work! <img src='http://etherealmind.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>The table you posted from Cisco is at this URL: <a href="http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080133ddd.shtml" rel="nofollow">http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080133ddd.shtml</a></p>
<p>At the end of the page we can find &#8220;Updated: Sep 30, 2008&#8243;.</p>
<p>There is another table too, on 6200networks.com by Joe Harris: <a href="http://6200networks.com/2008/09/30/ios-order-of-operation/" rel="nofollow">http://6200networks.com/2008/09/30/ios-order-of-operation/</a></p>
<p>This list has more entries than your Net≠work≠ers table, for example it covers reverse crypto maps.<br />
This post also is dated September 30th, 2008!</p>
<p>Who bids more? <img src='http://etherealmind.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Greg Ferro</title>
		<link>http://etherealmind.com/cisco-ios-order-of-operation/#comment-1217</link>
		<dc:creator>Greg Ferro</dc:creator>
		<pubDate>Tue, 08 Sep 2009 16:05:05 +0000</pubDate>
		<guid isPermaLink="false">http://etherealmind.com/?p=1697#comment-1217</guid>
		<description>&quot;Router Security Securing IP Control Planes BRKSEC-2105&quot; - This was from Cisco Networkers 2009 in Barcelona.</description>
		<content:encoded><![CDATA[<p>&#8220;Router Security Securing IP Control Planes BRKSEC-2105&#8243; &#8211; This was from Cisco Networkers 2009 in Barcelona.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Greg Ferro</title>
		<link>http://etherealmind.com/cisco-ios-order-of-operation/#comment-1216</link>
		<dc:creator>Greg Ferro</dc:creator>
		<pubDate>Tue, 08 Sep 2009 16:02:38 +0000</pubDate>
		<guid isPermaLink="false">http://etherealmind.com/?p=1697#comment-1216</guid>
		<description>Matt, 

I fixed the image and you should be able to get a larger image now.</description>
		<content:encoded><![CDATA[<p>Matt, </p>
<p>I fixed the image and you should be able to get a larger image now.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://etherealmind.com/cisco-ios-order-of-operation/#comment-1215</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Tue, 08 Sep 2009 14:42:07 +0000</pubDate>
		<guid isPermaLink="false">http://etherealmind.com/?p=1697#comment-1215</guid>
		<description>Can you please share what session you got that diagram from?</description>
		<content:encoded><![CDATA[<p>Can you please share what session you got that diagram from?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt Johnson</title>
		<link>http://etherealmind.com/cisco-ios-order-of-operation/#comment-1214</link>
		<dc:creator>Matt Johnson</dc:creator>
		<pubDate>Tue, 08 Sep 2009 14:09:13 +0000</pubDate>
		<guid isPermaLink="false">http://etherealmind.com/?p=1697#comment-1214</guid>
		<description>A larger version of that image would be great!</description>
		<content:encoded><![CDATA[<p>A larger version of that image would be great!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Served from: etherealmind.com @ 2012-02-11 05:41:58 by W3 Total Cache -->
